Govt Websites and Technical Glitches
If you think only Tax and Compliance websites have bugs and issues, read this article to know the fact that other Government websites have a history of ‘technical glitches’ too and they Need cyber hygiene, regular updates.
Several government Websites and even that of the Indian Army are running on software versions that are obsolete and need to upgraded to latest versions of software. You will be shocked to know that many key websites may still be compromised at the click of a button. Government needs to pay proper attention and have budgets for it. Its very very crucial for the nation. One hacking incidence can cost a lot to the country.
There was a funny (or not so funny) story. In the summer of 2018, the website of the Ministry of Defence became unresponsive with Mandarin characters appearing on the homepage, sparking fears of a Chinese cyberattack. But NIC explained later that the Mandarin characters were the logo of the content management tool Zen from a platform called Drupal that was used for the website.
Indian Army’s official website has been attacked multiple times over a decade and many government websites remain vulnerable even today.
Rajeev Chandrasekhar, who is the minister of state for electronics and information, informed the Rajya Sabha in December last year that in 2021, until October, India had 12,13,784 cybersecurity attacks compared with 11,58,208 breaches during 2020-21. Out of the total cases, 87,050 were against government organisations. That's a big number and worrisome.
One of the major reasons for such loopholes is outsourcing of tenders by original bidder without proper background verification and periodic audits of subcontractors.
For a long time, government agencies had followed the ‘L1 philosophy’ while awarding tenders. Which meant that the lowest bidder, and not the most qualified one, got the contracts to run and maintain the respective digital infrastructure. But in October 2021, the public-procurement division of the Department of Expenditure, Ministry of Finance, issued revised guidelines on the selection of bidders.
It has added an alternative procurement method, which is quality-cum-cost-based selection. So now it is no more allotment only on basis of cost. Qualification of the bidder will also be taken into account.
However, these guidelines may not be enough to make the entire digital ecosystem of the government foolproof. The primary bidders often outsource the security tasks to other firms. Such firms are sometimes not experienced enough. Such outsourcing is made many a times for profits and lack of skills with original bidder.
Both big and small firms are outsourcing their work in some way or the other. It is okay, provided there is an assurance on quality, reliability, and trustworthiness, which seems lacking in many cases.
Many a times, vendors are claiming expertise in areas in which they are not necessarily experienced in. They then rely on their subcontractors to fulfil certain critical parts of the project which can prove to be dangerous.
If such outsourcing is not done correctly, it could lead to unauthorised personnel gaining access to sensitive information, thereby increasing the risk of supply-chain attacks, threat to data through leaks, ransomware attacks, and a whole lot of other threats.
Many government websites are still using outdated versions of content management software (CMS) like Drupal. Just like any other software, timely updation to the most recent version of CMS is a crucial part of basic cyber hygiene. Outdated versions of software could help a bad actor to bypass IP and domain restrictions. Moreover, attackers from restricted or blocked domains could gain access to restricted web resources.
We all are aware that our respected Prime Minister’s Twitter account was briefly compromised in December 2021.
As per the reserach by CloudSEK which is a Cyber Security, Machine Intelligence company, a large number of government accesses and databases are being sold and auctioned on several cybercrime forums.
Digital India is welcome but it has to be done with responsibility and knowledge which is lacking in case of Government websites. It means Infosys fiasco is new to tax professionals but not so new for government. Let us know your comments on this.
This article is based on an article published in a leading newspaper in India.
Disclaimer: The information contained in this website is for general information purposes only. The information is provided by PracticeGuru and while we endeavour to keep the information up to date and correct, we make no representations or warranties of any kind, express or implied, about the completeness, accuracy, reliability, suitability or availability with respect to the website or the information, products, services, or related graphics contained on the website for any purpose. Any reliance you place on such information is therefore strictly at your own risk. In no event will we be liable for any loss or damage including without limitation, indirect or consequential loss or damage, or any loss or damage whatsoever arising from loss of data or profits arising out of, or in connection with, the use of this website.
Grow your practice with PracticeGuru
Write for PracticeGuru
Send your articles to [email protected]. We publish them on our website with credit to you. Read all articles.